Security & Trust overview
How Prime Fixel protects customer data across our website, engagements, and admin operations.
Web platform & hosting
HTTPS everywhere with HSTS
All traffic is served over TLS. HTTP Strict Transport Security is enabled with a two-year max-age, includeSubDomains, and preload eligibility.
Hardened response headers
Every response carries a Content Security Policy, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, and a restrictive Permissions-Policy that disables camera, microphone, and geolocation by default.
Row-level security on customer data
Customer records (inquiries, quotes, admin content) live in a managed Postgres database with row-level security policies. Public write endpoints (contact, quote) accept inserts only and never expose reads to anonymous visitors.
Safe rendering & sanitized links
User-supplied URLs stored in admin content are sanitized against javascript: and other unsafe schemes before render. Markdown output is escape-encoded; no arbitrary HTML from untrusted sources is inlined.
Admin access & identity
Multi-factor authentication for admins
Admins are required to enroll a TOTP authenticator and complete a step-up challenge before reaching privileged surfaces. Recovery codes are shown once at enrollment.
Least-privilege role model
Roles live in a dedicated user_roles table, never on profile records. Server functions verify the caller's role with a SECURITY DEFINER check before performing any privileged action.
Breached-password protection
New and rotated passwords are checked against the Have I Been Pwned k-anonymity API. Passwords found in known breaches are rejected during sign-up and password change.
Audit logging on admin actions
Privileged actions (role grants, inquiry status changes, MFA enrollment) are recorded with actor, timestamp, and target for after-the-fact review.
Data collection & retention
We collect only the information needed to respond to an inquiry or deliver a service you have requested — typically your name, business email, phone number, and a short description of your requirement. See our Privacy Policy for the full list of data categories, lawful bases, and retention windows.
Cookie usage, analytics, and consent choices are described in our Cookie Policy. Non-essential cookies load only after you accept them.
Contractual commitments — including service scope, service levels, and termination — are covered in our Terms & Conditions and Service Level Agreement.
What we do vs. what customers own
Prime Fixel responsibilities
- • Operating this website and its admin surfaces securely.
- • Applying the platform controls listed above.
- • Responding to security or privacy reports promptly.
- • Notifying affected customers of confirmed incidents.
Customer responsibilities
- • Keeping account credentials confidential.
- • Reviewing scoped access before granting our team system permissions.
- • Sharing sensitive information only through channels agreed in your engagement.
- • Reporting suspected misuse of your account to the contact below.
Report a security concern
If you believe you have found a vulnerability, a data-handling issue, or a suspicious account activity, please contact us. We investigate every credible report and will confirm receipt within one business day.
Have a compliance or security questionnaire?
Send it over and our team will respond with the completed document.
